Malware campaign that had been quite persistent with the Lumma Infostealer resurfaced in the recent years leveraging on malicious activities like SEO poisoning and pirated app downloads to hit Windows boxes. Social media baits or forged links stored in Google are used to trick clients seeking pirated programs to access affiliate sites. These include password-encrypted ZIP files with an NSIS installer polymorphically loaded within. When executed, Lumma, a password-harvesting infostealer that will steal session cookies, passwords, MFA tokens, crypto wallets, and browser private data, is executed. The malware infects openly and evades detection by antivirus software by the use of the CypherIT crypter, making it hard to detect through the use of standard signature-based detection techniques. Lumma, success-driven, took over "log" buying capability live marketplace, and endpoint defence-evading capability, is credited to Shamel, a Russian-speaking hacker. Microsoft, the US. DOJ, Europol, and Japanese authorities targeted Lumma's infrastructure, discredited over 2,300 domains, and found almost 400,000 hijacked computers in a global operation in May 2025. But malware writers are not slow to not let a good thing pass and start again with fresh command-and-control (C2) servers, proving their perseverance and the ever-evolving nature of cybercrime infrastructure. To gain the protection against such attacks, users and organizations need to deploy layered security. Do not use pirated software, install endpoint security, and utilize tools such as Splunk, Microsoft Sentinel, or CrowdStrike to identify LOLBins (such as tasklist.exe, findstr.exe) are crucial. Real-time hunting of threats along with scheduled patching and phishing training can lower the chances of Lumma infections in commercial and residential setups substantially.
Security researchers have identified a new variant of the SparkCat malware circulating on both the Apple App Store and Google Play Store, more than a year after its initial discove...
The European Union’s cybersecurity agency, CERT-EU, has attributed a significant cloud breach involving the European Commission to the TeamPCP threat group. The attack targeted t...
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...